ThreatBeaconXThreatBeaconXSubscribe
CriticalAPT · 6 min read · 35 views

jewelbug apt hijacks browsers steal cookies government networks

China-linked Jewelbug is conducting cyber-espionage campaigns against government organizations across the Middle East, Southeast Asia, and South Asia. The group uses malicious browser extensions, watering-hole attacks, browser cookie theft, fake software updates, and the Antino backdoor to monitor users and access sensitive government networks. More than one million implant check-ins, 580,000 stolen browser cookies, thousands of credentials, and over 2,300 stolen email bodies were identified.

Written by ThreatBeaconX Research Team·Published Aug 13, 2026

A China-based threat group tracked as Jewelbug has been observed conducting cyber-espionage operations against government organizations across the Middle East, Southeast Asia, and South Asia.

According to Symantec research reported by Cyber Security News, Jewelbug operates as a hackers-for-hire group combining government espionage with financially motivated cryptocurrency fraud.

The campaign has compromised government webmail environments, deployed malicious browser extensions, stolen browser cookies and credentials, and used compromised browsers as a pathway into internal networks.

Key Highlights

  • Threat actor: Jewelbug
  • Focus: Government and high-value organizations
  • Primary targets: Middle East, Southeast Asia and South Asia
  • More than 1 million implant check-ins observed
  • More than 580,000 browser cookies stolen
  • Thousands of credentials captured
  • More than 2,300 email bodies stolen
  • Malicious Chrome and Firefox extension named PDF Viewer
  • Browser control platform: XG-Web
  • Backdoor: Antino
  • Network implant: ClientKing
  • Uses Microsoft Graph API for C2
  • Uses watering-hole attacks against government webmail
  • Fake Adobe Flash/installer lures used to deliver malware

Browser Extension Abuse

A central component of the campaign is XG-Web, a browser-focused control system that allows operators to remotely interact with compromised browsers.

Jewelbug distributed a malicious Chrome and Firefox extension named:

PDF Viewer

Although presented as a legitimate document-reading extension, the extension requested excessive browser permissions.

Its capabilities included:

  • Reading browser cookies
  • Monitoring newly generated session tokens
  • Accessing browsing history
  • Accessing bookmarks
  • Capturing screenshots
  • Capturing clipboard contents
  • Injecting code into websites
  • Intercepting browser traffic

The stolen cookies could allow attackers to reuse authenticated sessions, potentially bypassing the protection normally provided by MFA when session cookies have already been compromised.

Native Browser Helper

The malicious extension communicated with a Windows helper process named:

com.microsoft.runedge

The component was designed to masquerade as a legitimate Microsoft Edge component.

This native helper allowed the attackers to extend their capabilities beyond the browser and execute commands on the compromised Windows system.

Antino Backdoor

Jewelbug also deployed the Antino backdoor.

Victims were exposed to fake Adobe Flash or Adobe installer downloads while visiting compromised government webmail environments.

Antino used Microsoft Graph API traffic for command and control, allowing malicious communications to blend into legitimate Microsoft cloud activity.

The combination of Antino and the browser extension provided attackers with both endpoint access and visibility into victims' online activity.

Watering-Hole Campaign

One of the largest observed campaigns targeted a shared government webmail platform in the Middle East.

Instead of compromising individual government ministries separately, Jewelbug injected a malicious script into the hosting environment supporting the shared webmail service.

When government personnel accessed affected login or mailbox pages, the script connected their browsers to attacker-controlled infrastructure.

The script could:

  • Collect browser cookies
  • Identify users through government email addresses
  • Select specific victims
  • Display fake software-update prompts
  • Target Windows users within selected government domains

This watering-hole technique allowed the attackers to reach high-value government users through a service they already trusted.

Credential and Session Theft

Browser session theft is one of the most significant aspects of this campaign.

By stealing valid browser cookies and session tokens, attackers may be able to reuse authenticated sessions without requiring the victim's password.

The campaign reportedly resulted in:

  • Over 580,000 stolen cookies
  • Thousands of captured credentials
  • More than 2,300 stolen email messages

Compromised sessions could provide access to sensitive correspondence and potentially serve as a stepping stone into additional internal services.

Internal Network Access

The campaign demonstrated that browser compromise can become a bridge into internal infrastructure.

Researchers observed attackers capturing authenticated traffic to a virtualization-management service from a compromised system.

This indicates that browser access was not limited to web surveillance and could potentially provide visibility into internal administrative systems.

ClientKing

Jewelbug also used a component named ClientKing.

ClientKing is a Linux and router implant capable of interacting with servers and network equipment.

This provides the threat actor with an additional mechanism to expand operations beyond individual Windows endpoints and browsers.

Financially Motivated Activity

Jewelbug's operations are not limited to espionage.

The same infrastructure and control panel were also associated with cryptocurrency fraud campaigns targeting Chinese-speaking victims.

These operations used:

  • Fake cryptocurrency exchange download pages
  • Search-result manipulation
  • Malicious download infrastructure

The overlap between espionage and financially motivated operations suggests that Jewelbug maintains a flexible infrastructure capable of supporting different objectives.

Detection and Hunting Opportunities

Security teams should monitor for:

  • Unauthorized Chrome or Firefox extensions
  • Extensions named PDF Viewer that request excessive permissions
  • Unexpected browser extension installations
  • Browser extensions accessing cookies or session tokens
  • Suspicious browser native-messaging registrations
  • Processes named com.microsoft.runedge
  • Unexpected browser-to-native-process communication
  • Fake Adobe Flash or Adobe installer downloads
  • Suspicious browser update prompts
  • Unauthorized scripts injected into government webmail pages
  • Large-scale browser cookie access
  • Unexpected Microsoft Graph API communication from non-Microsoft processes
  • Browser processes spawning suspicious child processes
  • Unexpected access to internal virtualization-management services
  • Suspicious connections from Linux servers or network devices

Recommended Mitigations

  1. Audit all installed browser extensions across the organization.
  2. Remove unauthorized or unnecessary browser extensions.
  3. Enforce enterprise browser extension allowlists.
  4. Monitor browser native-messaging registrations.
  5. Detect suspicious access to browser cookie stores.
  6. Monitor unexpected browser session-token activity.
  7. Inspect webmail platforms for unauthorized JavaScript.
  8. Monitor fake software-update prompts and suspicious download pages.
  9. Enable endpoint detection for masquerading processes such as com.microsoft.runedge.
  10. Monitor Microsoft Graph API usage for anomalous applications and processes.
  11. Rotate credentials and invalidate active sessions after suspected cookie theft.
  12. Segment administrative and virtualization-management interfaces from normal user networks.
  13. Monitor network equipment and Linux infrastructure for ClientKing-like activity.
  14. Review third-party hosting environments supporting government web applications.

Threat Assessment

Jewelbug represents a significant cyber-espionage threat because it combines browser compromise, cookie theft, credential collection, endpoint backdoors and watering-hole attacks.

The use of stolen browser sessions is particularly dangerous because authenticated cookies can provide access even when organizations have deployed MFA.

The campaign also demonstrates how a compromised government webmail platform can become a high-value distribution mechanism, allowing attackers to target many organizations through a shared trusted service.

Indicators of Compromise

  • e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf — HTA lure
  • 01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a — HTA downloader
  • e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34 — HTA lure
  • f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8 — TEST.hta
  • e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530 — slc.dll
  • b09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff — Antino backdoor
  • c11714f9fe2df1ca906585c81498cd77f5ec05b132aab73fa3a71d71d71e42cc — Antino backdoor
  • 0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd — Antino / Microsoft Graph sample
  • 9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3 — Adobe_installer (1).exe
  • fonts[.]tarotfree101[.]top — C2
  • fonts[.]chrorne[.]com — Payload hosting
  • robot[.]avbliud[.]com — C2
  • microsoft-flash[.]com — Malicious download infrastructure
  • www[.]wps-cn[.]com — C2
  • www[.]f1ash[.]org[.]cn — Malicious download infrastructure
  • browser-update[.]pages[.]dev — C2
  • eastus2[.]wac-azure[.]com — C2
  • mailbycloud[.]com — C2
  • www[.]jkskhei[.]com — C2
  • ns1[.]jkskhei[.]com — C2
  • dns[.]wizkidblogger[.]com — C2
  • 103[.]87[.]9[.]62 — Network indicator
  • 152[.]42[.]174[.]15 — Network indicator
  • 143[.]246[.]208[.]236 — Network indicator
  • 43[.]246[.]208[.]179 — Network indicator
  • 47[.]84[.]37[.]113 — Network indicator
  • 47[.]84[.]51[.]173 — Network indicator
  • 167[.]71[.]195[.]255 — Network indicator
  • 38[.]12[.]1[.]47 — Network indicator
  • 129[.]212[.]237[.]224 — Network indicator
  • 47[.]87[.]71[.]167 — Network indicator
  • 47[.]250[.]208[.]35 — Network indicator
  • 219[.]76[.]254[.]184 — Network indicator

Conclusion

Organizations should treat browser extensions as security-sensitive software and closely monitor their access to cookies, session tokens, browser history and native operating-system resources.

Government and critical-infrastructure organizations should also inspect shared webmail platforms for unauthorized scripts and monitor for fake update prompts, suspicious browser extensions, Microsoft Graph API anomalies and unexpected browser-to-endpoint process communication.

Where browser compromise is suspected, organizations should immediately invalidate affected sessions and rotate exposed credentials.

MITRE ATT&CK Mapping

T1189 — Drive-by CompromiseT1204.002 — User Execution: Malicious FileT1036 — MasqueradingT1547.001 — Registry Run Keys / Startup FolderT1176 — Browser ExtensionsT1539 — Steal Web Session CookieT1555.003 — Credentials from Web BrowsersT1056.003 — Web Portal CaptureT1059.003 — Windows Command ShellT1105 — Ingress Tool TransferT1071.001 — Web ProtocolsT1102 — Web ServiceT1566.002 — Phishing: Spearphishing LinkT1185 — Browser Session Hijacking